StepMat LogoStepMat
FeaturesScreenshotsFAQBlogReleases Download

Privacy Policy

Last updated: August 20, 2025

1. Controller

Matthias Siano
Weizenkamp 2
22081 Hamburg, Germany
Email: [email protected]

2. Data We Process

Account Data (Optional)

Email address - only if you voluntarily create an account to use social/leaderboard features.

Health & Activity Data

Step counts retrieved from Google Health Connect or local device sensors. We do not request more than steps.

Usage / Technical Data

Anonymous crash and performance diagnostics (device model, OS version, app version, timestamps, error traces).

Communication Data

Emails you send for support or inquiries.

3. Purposes & Legal Bases (GDPR)

  • •Providing core app functionality (local step tracking, progress): Art. 6(1)(b) GDPR (performance of contract)
  • •Social features (leaderboards, challenges): Art. 6(1)(b) GDPR; health data only after explicit consent (Art. 9(2)(a))
  • •Processing step count on backend (when social enabled): Art. 9(2)(a) GDPR (explicit consent)
  • •Crash & error diagnostics: Art. 6(1)(f) GDPR (legitimate interest in stability and security)
  • •Support requests (replying to emails): Art. 6(1)(f) GDPR (legitimate interest in user support)
  • •Legal compliance & security: Art. 6(1)(c)/(f) GDPR

You can withdraw consent at any time in the app settings; this does not affect prior lawful processing.

4. Data Retention

  • •Account & step data (social backend): Automatically deleted or anonymized after max. 60 days of inactivity or immediately when you delete your account
  • •Local-only data: Stored only on your device and removed when you uninstall the app
  • •Crash diagnostics: Retained only as long as needed for troubleshooting (typically less than 90 days)
  • •Support emails: Deleted after resolution, latest within 6 months

5. Hosting & Processing

Backend (social feature database) is hosted on Supabase (Frankfurt, Germany / EU). No transfer to non-EU/EEA countries. A Data Processing Agreement (Art. 28 GDPR) is in place with Supabase.

6. Data Sharing

We do not sell or share your data for advertising or profiling. Data is only processed by essential infrastructure providers (e.g. hosting, crash diagnostics) bound by contractual safeguards.

7. Your Rights (GDPR)

Access & Portability

Art. 15 (access) and Art. 20 (data portability)

Rectification & Restriction

Art. 16 (rectification) and Art. 18 (restriction)

Erasure & Objection

Art. 17 (erasure) and Art. 21 (objection, where applicable)

Withdraw Consent

Art. 7(3) GDPR and complaint right under Art. 77 GDPR

Exercise your rights anytime via [email protected]. For account deletion use the in-app function or email us.

8. Consent for Health (Step) Data

Step counts qualify as health-related data in context. We only process them on the backend for social features after your explicit opt-in. You can revoke consent anytime in settings; backend copies are then deleted (or queued for purge) and only local tracking remains.

9. Security

We apply industry-standard safeguards (least privilege access, encrypted transport (HTTPS/TLS), role-based database policies). No system is 100% secure, but we continually improve safeguards and minimize stored data.

10. Changes

We may update this policy for feature or legal changes. The latest version is always available here. Material changes will be highlighted in-app before they take effect.

Supervisory Authority (Germany)

You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). For Hamburg users the competent authority is:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22, 7. OG
20459 Hamburg, Germany
Tel: +49 40 428 54 4040
Website: datenschutz-hamburg.de
Email: [email protected]

No Data Protection Officer (DPO) is appointed because the criteria of Art. 37 GDPR (large-scale monitoring / special categories) are not met.

Terms of Service - StepMat Social Features

  • •Registration: Social features require a free account. Minimum age is 16 years.
  • •Community Rules: No insults, harassment, hate, discriminatory content, spam, automated misuse, or falsified activity data.
  • •Availability: We strive for high availability but do not guarantee uninterrupted uptime.
  • •Liability: We are only liable for intent and gross negligence as permitted by applicable law.
  • •Account Deletion: You can delete your account anytime in the app; associated backend data is removed immediately or within a short automated purge cycle.

Contact Us

If you have any questions about this Privacy Policy or want to exercise your rights, please contact us:

Email:[email protected]

Data Deletion:Request data deletion

Datenschutzhinweise (Kurzfassung auf Deutsch)

Deutsch anzeigen

Diese deutschsprachige Zusammenfassung dient nur der besseren Verständlichkeit. Verbindlich ist die obige englische Fassung.

Verantwortlicher

Matthias Siano, Weizenkamp 2, 22081 Hamburg, E-Mail: [email protected]

Welche Daten?

  • • Account (optional): E-Mail für soziale Funktionen
  • • Schrittanzahl (Health Connect / Sensor) - nur nach ausdrücklicher Zustimmung für soziale Features auf dem Server
  • • Nutzungs-/Crashdaten (anonymisiert)
  • • Support-Kommunikation per E-Mail

Zwecke & Rechtsgrundlagen

  • • App-Funktionen: Art. 6(1)(b) DSGVO
  • • Soziale Features / Leaderboard: Art. 6(1)(b); Gesundheitsdaten: Art. 9(2)(a) (Einwilligung)
  • • Stabilität / Fehleranalyse: Art. 6(1)(f)
  • • Support: Art. 6(1)(f)

Speicherdauer

  • • Account & Schritte (Server): max. 60 Tage Inaktivität oder sofort bei Löschung
  • • Lokale Daten: nur auf Deinem Gerät
  • • Support-Mails: bis Abschluss (unter 6 Monate)

Hosting

Supabase (Frankfurt/EU), keine Drittstaatenübermittlung.

Rechte

Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit, Widerruf, Beschwerde (Aufsichtsbehörde Hamburg).

Einwilligung

Kann jederzeit in den App-Einstellungen widerrufen werden; danach nur lokale Verarbeitung.

Sicherheit

Übliche technische und organisatorische Maßnahmen; geringstmögliche Datenspeicherung.

Soziale Funktionen - Regeln

Kein Missbrauch, Spam oder manipulierte Daten. Verstöße können zur Sperrung führen.

Letzte Aktualisierung: 20. August 2025

StepMat

Making walking fun, one step at a time! 🚶‍♀️
By Szanik

Legal

Privacy PolicyData DeletionImpressum

Resources

Distance CalculatorBlogFAQDownload

More

PausitiveFocuslist

© 2026 StepMat. All rights reserved.